Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.041exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow
CVE-2008-3704—remotewindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir ↗
Referência✓ VexDay Proof
TFT Gallery 0.10 - Password Disclosure
CVE-2006-1412—webappsphp
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3704—doswindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir ↗
Referência✓ VexDay Proof
ISPworker 1.21 - 'download.php' Remote File Disclosure
CVE-2007-5813—webappsphp
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC)
CVE-2008-3702—doswindows
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
CVE-2008-3680—dosmultiple
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
CVE-2009-0351—remotewindows
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
CVE-2008-6743—webappsphp
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlashBlog - 'articulo_id' SQL Injection
CVE-2008-2572—webappsphp
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
CVE-2008-6738—webappsphp
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xt-Stats 2.4.0.b3 (server_base_dir) - Remote File Inclusion
CVE-2007-0576—webappsphp
PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
InteliEditor 1.2.x - 'lib.editor.inc.php' Remote File Inclusion
CVE-2006-5527—webappsphp
PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlexPHPDirectory 0.0.1 - Authentication Bypass
CVE-2008-6750—webappsphp
Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Zomplog 3.8 - 'force_download.php' Remote File Disclosure
CVE-2007-2157—webappsphp
Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e-cart.biz Shopping Cart - Arbitrary File Upload
CVE-2009-1447—webappsphp
Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
CVE-2008-6921—webappsphp
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phsBlog 0.1.1 - Multiple SQL Injections
CVE-2008-3588—webappsphp
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GreenCart PHP Shopping Cart - 'id' SQL Injection
CVE-2008-3585—webappsphp
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component equotes 0.9.4 - SQL Injection
CVE-2008-2628—webappsphp
SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Aigaion 1.2.1 - 'DIR' Remote File Inclusion
CVE-2006-5930—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5061—webappsphp
Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Digital Eye CMS 0.1.1b - 'module.php' Remote File Inclusion
CVE-2007-1600—webappsphp
PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Drake CMS < 0.2.3 ALPHA rev.916 - Remote File Inclusion
CVE-2006-5767—webappsphp
PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DeluxeBB 1.3 - 'qorder' SQL Injection
CVE-2009-1033—webappsphp
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Konqueror 3.5.9 - 'load' Remote Crash
CVE-2008-5698—doslinux
HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Oracle APEX 3.2 - Unprivileged DB users can see APEX Password hashes
CVE-2009-0981—localmultiple
Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated u
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyKtools 2.4 - Arbitrary Database Backup
CVE-2008-6815—webappsphp
mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NoAh 0.9 pre 1.2 - 'filepath' Remote File Disclosure
CVE-2007-6187—webappsphp
Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6871—webappsasp
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
I-Pos Internet Pay Online Store 1.3 Beta - SQL Injection
CVE-2008-2634—webappsasp
SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers
23RIESGO
abrir ↗
← anteriorpágina 770 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.